LIVE · cybersecurity feed
Live wire
Malware Hijacks Android Car Head UnitsCritical Flaw in NASA/JPL Open-Source Spacecraft Command Software Allowed Unauthenticated Command ExecutionCVE-2026-73570 · U.S. CISA adds Zimbra Collaboration Suite (ZCS) flaw to its Known Exploited Vulnerabilities catalogCVE-2024-3094 · Connecting the Dots: Securing the Overlooked Corners of the Software Development Lifecycle (SDLC) Supply Chain14 Trojanized npm Packages Drop RedC2 4.0 Linux Backdoor With AI-Assisted C2Hundreds of leaked AWS keys give full control over corporate accountsAndroid Car Malware Spreads Through Built-In Updaters for Ad Fraud, Proxy BotnetMalware injected into popular Rust packages to steal developer credentialsSix Maximum-Severity Flaws Found in Cisco ProductsCritical Isolated-vm Vulnerability Leads to RCE on Host

social engineering

espionagehigh

Fake Conferences, OAuth and WhatsApp: Inside Russia’s New Espionage Tactics

Google's Threat Intelligence Group has identified three Russian-linked cyber espionage clusters (UNC6293, UNC7005, and UNC5976) employing sophisticated social engineering tactics. These groups exploit legitimate authentication features like OAuth and app passwords to compromise accounts of researchers, diplomats, and defense personnel. They utilize fake conference invitations, spoofed login pages, and even leverage AI-generated code for malware, posing a significant challenge to traditional security monitoring.

identity securityhigh

Inside the Modern SOC: The Identity Front Door

Attackers are increasingly leveraging compromised identities and social engineering tactics to gain initial access into corporate networks, bypassing traditional security measures. This shift means security teams must focus on identity context and behavioral analysis, rather than just login credentials, to detect and respond to threats effectively. Unified security telemetry and automated correlation are crucial for SOCs to identify sophisticated, identity-driven attacks before they escalate.

vishinghigh

UNC6671 Vishing Attacks Target Personal Phones to Steal SaaS Data

A sophisticated cybercrime group known as UNC6671 is employing vishing attacks, targeting employees' personal phones to steal SaaS data. The attackers impersonate IT support, tricking victims into fraudulent login portals that capture credentials and multi-factor authentication tokens. This allows them to gain access to cloud environments and applications like Microsoft 365 and Okta, deploying scripts for data exfiltration.

data breach

Levi Strauss says hackers breached employee computers, accessed corporate data

Levi Strauss & Co. has reported a cybersecurity incident where hackers gained unauthorized access to corporate data by compromising three employee-issued computers through a social engineering attack. The company stated that the breach was contained quickly, business operations were not disrupted, and there is no evidence that consumer data was affected. The investigation into the incident is ongoing, and no attackers have been identified.

aihigh

AI-generated phishing texts bypass human intuition

AI can craft highly convincing spear-phishing text messages that are difficult for even experienced individuals to distinguish from legitimate communications. A demonstration showed that personalized AI-generated texts, mimicking official alerts, could easily deceive recipients, highlighting the limitations of relying on gut feelings to identify threats.

aihigh

ESET tracks rise in malicious AI skills and adaptable malware

Cybercriminals are increasingly leveraging artificial intelligence and adapting existing techniques to enhance their operations, according to ESET's H1 2026 Threat Report. Attackers are utilizing AI skills for malicious purposes and incorporating generative AI into malware, exemplified by Android malware PromptSpy. Social engineering tactics like ClickFix and quishing are also evolving, while ransomware attacks persist despite a decrease in ransom payments.

aihigh

3 Ways AI Powers Service Desk Attacks and How to Prevent Them

Artificial intelligence is increasingly being used by attackers to enhance service desk attacks, particularly during employee onboarding. AI tools can create more convincing impersonations, accelerate reconnaissance for personalized attacks, and scale malicious campaigns. To counter these threats, organizations need to implement stronger identity verification methods, such as secure password delivery, biometric liveness detection, and multi-factor authentication before sensitive actions are approved.

phishing

Big Brand Jobs Scam Targets Marketing Pros' Google Accounts

A sophisticated phishing campaign is targeting marketing professionals by using fake job offers from major brands. This scheme employs nested redirects to bypass detection and aims to steal Google account credentials.

social engineeringhigh

How the Reddit and Discord false report scam steals accounts

Scammers are targeting users on platforms like Reddit and Discord by initiating conversations under the guise of a mistaken account report. They aim to trick victims into revealing login credentials or verification codes, or into changing their account's linked email address. The ultimate goal is to gain unauthorized access to accounts, lock users out, or extort payment by threatening account deletion or misuse.